首页> 外文会议>International Conference on Applied Human Factors and Ergonomics >How management goes wrong? - The human factor lessons learned from a cyber incident handling exercise
【24h】

How management goes wrong? - The human factor lessons learned from a cyber incident handling exercise

机译:管理如何出错? - 从网络事件处理锻炼中汲取的人为因素经验

获取原文
获取外文期刊封面目录资料

摘要

A cybersecurity hazard in a Critical Infrastructure (CI) is not only about computer malfunction, but is also affecting safety and business continuity of CI. The study on human contribution to cyber resilience is unexplored terrain in the field of critical infrastructure security. So far cyber resilience has been discussed as an extension of the IT security research. Although cybersecurity training is a common measure to implement because of its low cost, most of the training courses aim at improving security awareness of employees, in order to prevent the human-error. However, this approach does not address resilience in handling a cyber incident. The authors conducted observations in a full-scale adversarial cyber security training for CI, where participants are divided into an offensive and a defensive team. The latter acts as one organization and its members play assigned roles such as manager, factory operator and IT administrator. From our observations, some tendencies are found in the defensive team's negative social behaviors and the management issues that lead to malfunction of the team. In fact, these behaviors are perceived in every group of participants, regardless of the variation in their experience and in knowledge on the field. In this paper, the findings from the above mentioned observations are presented as possible challenges in real-world cyber incident management.
机译:关键基础设施(CI)中的网络安全危害不仅是计算机故障,而且还影响CI的安全和业务连续性。对网络恢复力的人类贡献的研究是关键基础设施安全领域的未开发地形。到目前为止,已经讨论了网络弹性作为IT安全研究的延伸。虽然网络安全培训是由于其成本低,大多数培训课程旨在提高员工的安全意识,以防止人为错误。但是,这种方法在处理网络事件时不会解决恢复力。作者对CI的全面对抗网络安全培训进行了观察,参与者分为令人反感和防守团队。后者充当一个组织,其成员扮演分配的角色,例如经理,工厂运营商和IT管理员。从我们的观察结果来看,在防守团队的负面社会行为和导致团队故障的管理问题中发现了一些趋势。事实上,这些行为在每一群参与者中都被察觉,无论他们经验的变化以及对该领域的知识。在本文中,在现实世界网络事件管理中可能存在上述观察结果的发现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号